This policy applies to Lacak's marketing website, registration and billing flows, web and mobile applications, attribution, CRM, outbound messaging, support, and integrations enabled by a customer. It is the English translation of the Indonesian policy; the Indonesian version governs if the two differ.
1. Scope and identity
The service is operated by Lacak. Privacy questions may be sent to[email protected].
This policy follows Law of the Republic of Indonesia No. 27 of 2022 on Personal Data Protection (“the PDP Law”) and its implementing regulations, together with other law applicable to a particular relationship.
2. Data processed
Account and workspace data
Names, email addresses, phone numbers, organization, role, preferences, invitation status, devices, sessions, and information required to create and secure an account. This is normally the data of the business customer's own staff.
Billing and transaction data
Product, plan, billing period, invoice, payment status, usage credits, and transaction references. Payment-instrument details may be processed directly by the payment provider and may not be stored by Lacak.
End-customer contact data
Contact identities, WhatsApp numbers and other communication routes, acquisition source, campaign, activity, sales work, purchases, transaction value, documents, notes, assignment, and workflow information entered or connected by the business customer.
Conversation content and media
In the full CRM product, Lacak stores WhatsApp conversation content and the media sent and received through the numbers a customer connects, on that business customer's behalf. Conversation content and media are stored encrypted and are reachable only by the workspace that owns them. Lacak also processes limited metadata needed for identity, routing, status, attribution, security, and reconciliation. Customer conversations are not read for Lacak's own marketing and are not used as another business's data.
Integration, technical, and support data
Connected account or asset identifiers, permissions, configuration, events, webhooks, campaign metrics, advertising cost, network and device information, authentication events, request status, error classes, audit records, performance signals, support messages, and attachments.
3. Why data is used
- Create, authenticate, and secure accounts and workspaces.
- Provide attribution, CRM, messaging, documents, outbound, reporting, and mobile functions.
- Connect acquisition sources, conversations, customers, sales work, and purchases.
- Operate billing, usage credits, support, and service communications.
- Detect abuse, isolate access, recover failures, and audit important changes.
- Meet legal obligations and respond to valid requests.
- Improve the product using restricted usage information; customer conversations are not read for Lacak's advertising.
A processing basis may include performance of a contract, consent, legitimate interest, a legal obligation, or another available basis. For end-customer data, the basis is determined and assured by the business customer.
4. Controller and processor roles
For account, billing, security, and direct user relationships, Lacak acts as the Personal Data Controller, because Lacak determines the processing required to provide and protect the service.
For end-customer data — contact identities, conversation content, media, and commercial records entered or connected through a workspace — the business customer is the Personal Data Controller and Lacak is the Personal Data Processor. Lacak processes that data only on the business customer's instructions and only as needed to provide the service.
As Controller, the business customer is responsible for the lawful basis toward its own customers, including notices, consent where required, communication preferences, suppression lists, data accuracy, and retention instructions. Lacak may reject an instruction that clearly conflicts with law, security, provider rules, or another person's rights.
5. Storage, data location, and cross-border transfer
Lacak service data is stored and processed on Cloudflare, Inc. infrastructure in the Asia-Pacific (Singapore) region.
Personal data originating in Indonesia is therefore stored and processed outside Indonesian territory. That storage and processing is a cross-border transfer of personal data under the PDP Law. By using Lacak, the business customer as Controller is aware of and accepts that transfer, and is responsible for informing its own customers as its obligations require.
For cross-border transfers, Lacak and the customer rely on contractual mechanisms, protection assessments, and other safeguards appropriate to their respective roles and applicable law. Channel, cloud, payment, or other integrations selected by the customer may also process data in other countries under their own terms.
6. Security
Lacak uses technical and organizational controls proportionate to risk, including:
- encryption in transit and encryption at rest, with keys separated per business so one workspace's data cannot be opened with another workspace's key;
- access control by business and by role, so permissions follow the work a user actually does;
- durable audit records for important changes, so who did what and when remains reviewable;
- credential protection, testing, backups, recovery procedures, and limits on data placed in logs and background work.
This policy describes protections in general terms and does not publish architecture detail. No service can promise zero risk. Users must protect their credentials, devices, provider permissions, and workspace membership.
7. Sharing and subprocessors
Lacak relies on the following providers to operate the service:
- Cloudflare, Inc. — the compute, storage, network, and security infrastructure the service runs on.
- Meta Platforms, Inc. — the WhatsApp Business Platform used to send and receive messages on the numbers a customer connects. WhatsApp messaging is subject to Meta's own terms and policies, and Lacak does not control Meta's decisions about a customer's account, number, or templates.
Data may also be shared on a limited basis with:
- other communications, security, observability, and technical support providers needed to run the service;
- channel providers, advertising platforms, payment providers, and integrations enabled by the customer;
- professional advisers subject to confidentiality obligations;
- authorities or other parties when required by law or necessary to protect rights and safety; and
- a lawful successor in a corporate transaction, subject to appropriate protections.
The current subprocessor list is available on request at[email protected]. Lacak does not sell end-customer data as a marketing list.
8. Retention, quotas, and deletion
Data is retained for as long as needed to provide the service, maintain security and auditability, resolve disputes, meet legal obligations, and carry out the customer's valid retention instructions. Retention of end-customer data follows the customer's plan terms and the business customer's instructions as Controller.
Cache, operational logs, transaction evidence, backups, and commercial records have different purposes and retention cycles. Account deletion does not necessarily remove every backup copy immediately; backup copies age out through their retention cycle and remain restricted.
Each plan includes a media and data storage quota. When a quota is reached, stored data is not deleted automatically. Instead, new media storage is blocked until the customer adds quota or frees space.
Export and deletion requests are subject to authorization, active disputes, legal retention duties, and data belonging to others. See Data Deletion for request instructions.
9. Rights of data subjects
Under the PDP Law and other applicable law, a data subject may request information about processing, access to and a copy of their data, correction, deletion or destruction, restriction of processing, withdrawal of consent, objection to automated decision-making, and portability.
For information controlled by a business through Lacak, submit the request to that business first as Controller. Lacak as Processor supports valid access and deletion requests through the business customer, under the service agreement and available product controls, and does not answer such requests directly without the Controller's instruction.
Verification of identity and scope may be required to prevent disclosure or deletion at the request of the wrong person.
10. Breach notification
If a personal data protection failure affects customer data, Lacak notifies the affected business customers without undue delay after the incident is identified and confirmed, consistent with its obligations under the PDP Law.
The notice includes the information available about the categories of data affected, the timing, and the containment and recovery steps taken. The business customer as Controller is responsible for notifying data subjects and the competent authority as its own obligations require, and Lacak assists with the information it holds.
A suspected security incident may be reported at any time to[email protected].
11. Cookies and analytics
The lacakbisnis.id marketing website uses Cloudflare Web Analytics to measure visits and page performance without analytics cookies, advertising cookies, or visitor profiling.
The Lacak application uses cookies or storage that are strictly necessary to maintain a signed-in session and account security. None of this storage is used for advertising profiling.
12. Changes
This policy may be updated when the product, providers, processing practices, or legal duties change. The effective date above will be updated. Material changes may also be communicated through the product, email, or another reasonable channel where required.
13. Contact
Send privacy questions, requests, or suspected incidents to[email protected]. Include the workspace, your relationship to the information, and a specific request. Do not send passwords, tokens, or unnecessary confidential information. Commercial terms are described in theTerms of Service.